Lucene search

K
nvd[email protected]NVD:CVE-2022-43252
HistoryNov 02, 2022 - 2:15 p.m.

CVE-2022-43252

2022-11-0214:15:15
CWE-787
web.nvd.nist.gov
4
cve-2022-43252
libde265
fallback-motion.cc
denial of service
crafted video file

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

47.9%

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

Affected configurations

Nvd
Node
strukturlibde265Match1.0.8
Node
debiandebian_linuxMatch10.0
OR
debiandebian_linuxMatch11.0

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

47.9%